Non Admin vs Domain Admin for syncing to destination AD

Created: 2012-04-20 08:09:59
Modified: 2023-06-09 10:29:34
Tags: Active Directory Troubleshooting UnitySync

UnitySync performs most easily if the destination login account is a Domain Admin. This is because only a domain admin can read the destination roots for legacyExchangedn, x400 and showInAddressBook. When you use a domain admin account, your UnitySync connection can automatically detect and set the appropriate values for these attributes.

If your Destination login is not a domain admin, or your first test sync indicates the detected roots are not valid, you may hard code mappings using the appropriate values for each attribute.


If legacyExchangeDN roots are not being properly detected, you will see the following error in your Run Summary:

LegacyExchangeDN Failure | 1
Fatal Error | 1

In the Destination Configuration Discovery section of your log, you’ll also see:

LegacyExchangeDN | Failed to Detect - No Entries Found

There is a work around for this error. Please refer to setting exch-legdn for instructions to override legacyExchandeDN detection by setting the legacyexchangedn attribute.

NOTE: While this error is most commonly seen when you are not able to use domain admin for your Destination, some clients have also reported the error even if they are using domain admin login credentials. Often, this is due to Exchange Forest Prep being run on the destination, without Exchange also being installed. If this is the case with your Destination, please contact for assistance in disabling legacyexchangeDN detection.


If x400 roots are not being properly detected, you may see the following error in the Error Summary at the end of your log:

32: No such object | 1

If you search your log for 32:, you’ll likely also see the following in the Destination Configuration Discovery section of your log:

X400 Template | Failed to Detect 
LDAP Return | 32: No such object 
LDAP Message | 0000208D: NameErr: DSID-031522C9, problem 2001 (NO_OBJECT), data 0, best match of: 
'CN=ABC,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=ABC,DC=COM'

There is a work around for this error. Please see setting exch-x400 to override detection by setting the x400 root.


If the address books cannot be automatically detected, or if those detected are not valid, you may see an error similar to the following after each attempt to add an object:

Adding User |,OU=ABC Users,DC=abc,DC=com 
Add Person Return | 19:000020B5: AtrErr: DSID-03152804, #1:  
0: 000020B5: DSID-03152804, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 90284 (showInAddressBook)

There is a work around for this error. Please see setting showInAddressBook to set the showInAddressBook attributes properly.

Error on Structure creation

Finally, domain admin credentials are needed to allow your sync to create necessary structure. Alternatively, you may use Special Permissions on a specified sync container as a work around.

Share this article:

  1. Directify - Self Service

  2. Mimic - Replication

  3. UnitySync - Sync
  1. emPass - Sync
  1. Profiler
  2. SimpleSync